CVE-2014-7852 – RichFaces: Cross-site scripting due to incomplete URL sanitization
https://notcve.org/view.php?id=CVE-2014-7852
Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web script or HTML via crafted URL, which is not properly handled in a CSS file. Vulnerabilidad de XSS en JBoss RichFaces, utilizado en JBoss Portal 6.1.1, permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de una URL manipulada, lo cual no se maneja correctamente en un fichero CSS. It was found that RichFaces accepted arbitrary strings included in a URL and returned them unencoded in a CSS file. A remote attacker could use this flaw to perform cross-site scripting (XSS) attacks against a user running a RichFaces application. • http://rhn.redhat.com/errata/RHSA-2014-1973.html http://www.securitytracker.com/id/1031363 https://access.redhat.com/security/cve/CVE-2014-7852 https://bugzilla.redhat.com/show_bug.cgi?id=1164024 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •